Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Allow reviews for registered projects - #44

Merged
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews
Aug 2, 2026
Merged

Allow reviews for registered projects#44
logancsack merged 4 commits into
mainfrom
fix/allow-registered-project-reviews

Conversation

@logancsack

@logancsacklogancsack commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Problem

Managed Aldo Review requests can target an active project registered outside the server startup cwd, but review path validation only allowed the configured workspace root and T3 worktrees. The settings UI also allowed users to type arbitrary repositories before GitHub proved installation ownership.

Solution

  • allow review cwd values under an active registered orchestration project while retaining canonical-path and worktree boundaries
  • remove arbitrary repository entry from Aldo Review settings
  • guide users through GitHub App installation/synchronization and keep disconnected repositories visibly fail-closed

Verification

  • focused ReviewService and settings tests: 7 passed
  • vp run typecheck: passed (existing Effect suggestions only)
  • scoped lint: passed
  • managed production build on pinned Node 24.13.1: passed
  • managed browser QA: 1440x900 and 390x844 passed with no horizontal overflow

No schema, credential, or desktop-release changes.

Summary by CodeRabbit

  • New Features

    • Review previews now support nested working directories within registered projects.
    • Grok Review repositories are automatically discovered and listed from the server.
    • Configure each repository with provider, model, and enablement controls.
    • Added options to manage or reinstall the GitHub app when repository access is disconnected.
  • Improvements

    • Removed manual repository entry and validation.
    • Updated empty-state and connection messaging to reflect automatic repository discovery.

@logancsack
logancsack marked this pull request as ready for review August 2, 2026 03:39
@cursor

cursorBot commented Aug 2, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:L labels Aug 2, 2026
@coderabbitai

coderabbitaiBot commented Aug 2, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@logancsack, you've reached your PR review limit, so we couldn't start this review.

Next review available in:25 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d670fa22-3648-4547-bc75-b2960a2e90b5

📥 Commits

Reviewing files that changed from the base of the PR and between ce23508 and 1e04c9f.

📒 Files selected for processing (2)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
📝 Walkthrough

Walkthrough

The review service now accepts nested working directories within active registered projects by querying ancestor paths. Grok Review settings now use server-discovered repositories and remove manual repository creation controls.

Changes

Workspace validation

Layer / File(s)Summary
Ancestor project validation
apps/server/src/review/ReviewService.ts, apps/server/src/review/ReviewService.test.ts
ReviewService resolves workspace paths, checks active project ancestors, converts query failures to repository-detection errors, and validates nested working directories before VCS detection. Tests cover ancestor queries and accepted nested paths.

Grok Review settings

Layer / File(s)Summary
Server-discovered repository configuration
apps/web/src/components/settings/GrokReviewSettings.tsx, apps/web/src/components/settings/GrokReviewSettings.test.ts
The settings UI removes manual repository entry and related validation. Installation, disconnected-repository, and empty-state messages now describe GitHub-based repository discovery and management.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers:juliusmarminge

Poem

A rabbit checks each path in line,
Through project roots it hops just fine.
The settings shed the manual gate,
GitHub now helps discover and state.
“Refresh,” it says, with ears held high.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.
Title check✅ PassedThe title clearly summarizes the primary change: allowing reviews for registered projects.
Description check✅ PassedThe description covers the problem, solution, verification, and UI impact, but it omits the template headings, checklist, and screenshots.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/allow-registered-project-reviews

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:ce23508ad4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/server/src/review/ReviewService.ts`:
- Around line 101-104: Update the authorization condition in getDiffPreview to
validate only the canonical candidate path, removing the lexical-path ancestor
check that allows symlink escapes from registered projects. Add a regression
test covering a symlink inside a registered project targeting an unregistered
directory, asserting the request fails and detect is not called.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ca7b44d1-4d9d-42a9-9dc1-26699190702e

📥 Commits

Reviewing files that changed from the base of the PR and between 606275e and ce23508.

📒 Files selected for processing (4)
  • apps/server/src/review/ReviewService.test.ts
  • apps/server/src/review/ReviewService.ts
  • apps/web/src/components/settings/GrokReviewSettings.test.ts
  • apps/web/src/components/settings/GrokReviewSettings.tsx

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:0bfade9d22

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:31428592d3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadapps/server/src/review/ReviewService.ts Outdated
@logancsack
logancsack merged commit fc636e5 into mainAug 2, 2026
12 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:Lvouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@logancsack@codex